<?php
session_start();
include_once('config.php');

function set_cookie_sosanh($name, $value = ""){
	$expire_date = time() + 60*60;
	return setcookie($name,$value,$expire_date,"/","");
}

if(@$_POST['autoview_sosanh']){
	$id = explode(',',$_SESSION['sosanh']);
	if(count($id)>2){
		for($i=1; $i<=3; $i++){
			if($id[$i]!='') $str .= " OR id='{$id[$i]}'";
		}
		$str = trim($str,' OR ');
		$qr = $tc->autoview_sosanh($str);
		while($row = mysql_fetch_array($qr)){
			echo '<div class="item_sosanh item_sosanh_'.$row['id'].'">
				<a href="'.$tc->link_detail($row['menu_id']).$row['name_rewrite'].'.html"><img src="'.url_product_thumb.$row['url_hinh'].'" alt="thumb '.$row['name'].'" />
				<p>'.$row['name'].'</p></a>
				<div class="delete_sosanh delete_sosanh_'.$row['id'].'" title="xóa">x</div>
			</div>';
		}
	}
}

if(@$_POST['addsosanh']){
	$id = explode(',',$_SESSION['sosanh']);
	if(count($id)>4) return false;
	if(!@$_SESSION['sosanh']) $_SESSION['sosanh'] = ',';
	$id = $_POST['id'];
	$subject = $_SESSION['sosanh'];
	$pattern = "/,{$id},/i";
	if(!preg_match($pattern,$subject)){
		$_SESSION['sosanh'] = $_SESSION['sosanh'].$id.',';
		$qr = $tc->add_sosanh($id);
		$row = mysql_fetch_array($qr);
		echo '<div class="item_sosanh item_sosanh_'.$id.'">
			<a href="'.$tc->link_detail($row['menu_id']).$row['name_rewrite'].'.html"><img src="'.url_product_thumb.$row['url_hinh'].'" alt="thumb '.$row['name'].'" />
			<p>'.$row['name'].'</p></a>
			<div class="delete_sosanh delete_sosanh_'.$id.'" title="xóa">x</div>
		</div>';
	}else return true;
}

if(@$_POST['delsosanh']){
	$id = $_POST['id'];
	$subject = $_SESSION['sosanh'];
	$pattern = "/,{$id},/i";
	if(preg_match($pattern,$subject)){
		$str = str_replace(",{$id},",",",$subject);
		$_SESSION['sosanh'] = $str;
		return true;
	}else return false;
}

if(@$_POST['view_sosanh']){
	$id = explode(',',$_SESSION['sosanh']);
	if(count($id)>3){
		for($i=1; $i<=3; $i++){
			if($id[$i]!='') $str .= " OR id='{$id[$i]}'";
		}
		$str = trim($str,' OR ');
		$qr = $tc->autoview_sosanh($str);
		while($row = mysql_fetch_array($qr)){
			$url_hinh[] = '<img height="120" src="'.url_product_thumb.$row['url_hinh'].'" alt="" />';
			$name[] = "<p style='text-align:center; font-weight:bold; padding-top:10px'>{$row['name']}</p>";
			$price[] = '<p style="color:#F00; padding-top:5px">'.number_format($row['price'],0,',','.').'đ</p>';
			$link[] = $tc->link_detail($row['menu_id']).$row['name_rewrite'].'.html';
			$cpu[] = $row['cpu'];
			$ram[] = $row['ram'];
			$manhinh[] = $row['manhinh'];
			$camera[] = $row['camera'];
			$camera_phu[] = $row['camera_phu'];
			$pin[] = $row['pin'];
			$os[] = $row['os'];
			$quayphim[] = $row['quayphim'];
			$bonhotrong[] = $row['bonhotrong'];
			$thenho[] = $row['thenho'];
		}
		echo '<table width="890" border="0" cellpadding="0" cellspacing="0" id="view_sosanh">
            <tr><td width="110">&nbsp;</td><td width="260" align="center"><a href="'.$link[0].'">'.$url_hinh[0].$name[0].'</a>'.$price[0].'</td><td width="260" align="center"><a href="'.$link[1].'">'.$url_hinh[1].$name[1].'</a>'.$price[1].'</td><td width="260" align="center"><a href="'.$link[2].'">'.$url_hinh[2].$name[2].'</a>'.$price[2].'</td></tr>
            <tr><td width="110">CPU:</td><td>'.$cpu[0].'</td><td>'.$cpu[1].'</td><td>'.$cpu[2].'</td></tr>
            <tr><td>RAM:</td><td>'.$ram[0].'</td><td>'.$ram[1].'</td><td>'.$ram[2].'</td></tr>
            <tr><td>Màn hình:</td><td>'.$manhinh[0].'</td><td>'.$manhinh[1].'</td><td>'.$manhinh[2].'</td></tr>
            <tr><td>Camera:</td><td>'.$camera[0].'</td><td>'.$camera[1].'</td><td>'.$camera[2].'</td></tr>
            <tr><td>Camera phụ:</td><td>'.$camera_phu[0].'</td><td>'.$camera_phu[1].'</td><td>'.$camera_phu[2].'</td></tr>
            <tr><td>PIN:</td><td>'.$pin[0].'</td><td>'.$pin[1].'</td><td>'.$pin[2].'</td></tr>
            <tr><td>OS:</td><td>'.$os[0].'</td><td>'.$os[1].'</td><td>'.$os[2].'</td></tr>
            <tr><td>Quay phim:</td><td>'.$quayphim[0].'</td><td>'.$quayphim[1].'</td><td>'.$quayphim[2].'</td></tr>
            <tr><td>Bộ nhớ trong:</td><td>'.$bonhotrong[0].'</td><td>'.$bonhotrong[1].'</td><td>'.$bonhotrong[2].'</td></tr>
            <tr><td>Thẻ nhớ:</td><td>'.$thenho[0].'</td><td>'.$thenho[1].'</td><td>'.$thenho[2].'</td></tr>
        </table>';
	}
}

if(@$_POST['view_muahang']){
	$qr = $tc->add_sosanh($_POST['id']);
	$row = mysql_fetch_array($qr);
	echo '<div style="line-height:22px"><img style="height:120px; float:left; margin-right:10px" src="'.url_product_thumb.$row['url_hinh'].'" alt="'.$row['name'].'" />
	<p style="font-weight:bold; font-size:150%">'.$row['name'].'</p><p style="font-weight:bold; color:#F00">'.number_format($row['price'],0,',','.').'đ</p></div>
	<div style="clear:both; height:30px"></div>
	<table width="100%" border="0" cellspacing="0" cellpadding="0" id="form_lienhe">
	  <tr>
		<td width="10%">Họ &amp; tên: <span style="color:#FF0000">*</span></td>
		<td width="40%"><input type="text" name="name" maxlength="50" class="txt" /></td>
		<td width="10%">Điện thoại: <span style="color:#FF0000">*</span></td>
		<td width="40%"><input type="text" name="phone" maxlength="20" class="txt" /></td>
	  </tr>
	  <tr>
		<td>Email: <span style="color:#FF0000">*</span></td>
		<td><input type="text" name="email" maxlength="50" class="txt" /></td>
		<td>Địa chỉ: <span style="color:#FF0000">*</span></td>
		<td><input type="text" name="diachi" maxlength="200" class="txt" /></td>
	  </tr>
	  <tr>
		<td valign="top" style="padding-top:10px">Yêu cầu:</td>
		<td colspan="3"><textarea name="content" class="textarea"></textarea></td>
	  </tr>
	  <tr>
		<td>&nbsp;</td>
		<td colspan="3"><input type="submit" name="submit_muahang" value="Đặt mua" class="btn" /></td>
	  </tr>
	</table>';
}

if(@$_POST['form_danhgia_sp']){
	echo '<div style="line-height:22px"><p style="font-weight:bold; font-size:150%">Đánh giá sản phẩm</p></div>
	<div style="clear:both; height:30px"></div>
	<table width="100%" border="0" cellspacing="0" cellpadding="0" id="form_lienhe">
	  <tr>
		<td width="10%">Họ &amp; tên: <span style="color:#FF0000">*</span></td>
		<td width="40%"><input type="text" name="name" maxlength="50" class="txt" /></td>
		<td>Email: <span style="color:#FF0000">*</span></td>
		<td><input type="text" name="email" maxlength="50" class="txt" /></td>
	  </tr>
	  <tr>
		<td valign="top" style="padding-top:10px">Đánh giá: <span style="color:#FF0000">*</span></td>
		<td colspan="3"><textarea name="content" class="textarea"></textarea></td>
	  </tr>
	  <tr>
		<td>&nbsp;</td>
		<td colspan="3"><input type="submit" name="submit_danhgia" value="Gửi đi" class="btn" /></td>
	  </tr>
	</table>';
}

if(@$_POST['view_datmua_sim']){
	echo '<div style="line-height:22px"><img style="height:100px; float:left; margin-right:30px" src="images/sim_so.jpg" />
	<p style="font-weight:bold; font-size:150%; padding:20px 0 10px 0">Đặt mua SIM số: '.$_POST['name'].'</p><p style="font-weight:bold; color:#F00; font-size:120%">Giá: '.$_POST['price'].'</p></div>
	<div style="clear:both; height:30px"><span id="id_sim" style="display:none">'.$_POST['id'].'</span></div>
	<table width="100%" border="0" cellspacing="0" cellpadding="0" id="form_lienhe">
	  <tr>
		<td width="10%">Họ &amp; tên: <span style="color:#FF0000">*</span></td>
		<td width="40%"><input type="text" name="name" maxlength="50" class="txt" /></td>
		<td width="10%">Điện thoại: <span style="color:#FF0000">*</span></td>
		<td width="40%"><input type="text" name="phone" maxlength="20" class="txt" /></td>
	  </tr>
	  <tr>
		<td>Email: <span style="color:#FF0000">*</span></td>
		<td><input type="text" name="email" maxlength="50" class="txt" /></td>
		<td>Địa chỉ: <span style="color:#FF0000">*</span></td>
		<td><input type="text" name="diachi" maxlength="200" class="txt" /></td>
	  </tr>
	  <tr>
		<td valign="top" style="padding-top:10px">Yêu cầu:</td>
		<td colspan="3"><textarea name="content" class="textarea"></textarea></td>
	  </tr>
	  <tr>
		<td>&nbsp;</td>
		<td colspan="3"><input type="submit" name="submit_muasim" value="Đặt mua" class="btn" /></td>
	  </tr>
	</table>';
}

if(@$_POST['add_danhgia_sp']){
	$product_id = trim($_POST['id']);
	$name = trim($_POST['name']);
	$email = trim($_POST['email']);
	$content = $tc->remove_tag_html(trim($_POST['content']));
	if(strlen($name)>2 && strlen($content)>10 && $tc->check_email($email)==true){
		$tc->insert_danhgia_sp($name,$email,$content,$product_id);
		echo '<div class="item_danhgia"><h6>'.$name.$product_id.'</h6><p>'.$content.'</p></div>';
	}else echo 0;
}

if($_POST['contact']=='contact'){
	$name = trim($_POST['name']);
	$email = trim($_POST['email']);
	$phone = trim($_POST['phone']);
	$diachi = trim($_POST['diachi']);
	$content = trim($_POST['content']);
	if($name!='' && $email!='' && $content!=''){
		if($tc->insert_contact($name,$email,$phone,$diachi,$content)){
			echo '1';
			include_once('sendmail/sendmail.php');
			return true;
		}else{
			echo '0';
			return false;
		}
	}else{
		echo '0';
		return false;
	}
}

if(@$_POST['dathang']){
	$product_id = trim($_POST['id']);
	$name = trim($_POST['name']);
	$email = trim($_POST['email']);
	$phone = trim($_POST['phone']);
	$diachi = trim($_POST['diachi']);
	$content = trim($_POST['content']);
	$link_sp = 'http://'.$domain.trim($_POST['link_sp']);
	if($name!='' && $phone!='' && $diachi!='' && $tc->check_email($email)==true){
		$tc->insert_products_order($name,$email,$phone,$diachi,$content,$product_id,$link_sp);
		echo '1';
		$qr = mysql_query("SELECT name FROM `products` WHERE `delete`=0 AND status=1 AND id ='{$product_id}'");
		$row = mysql_fetch_array($qr);
		$name_sp = $row['name'];
		include_once('sendmail/sendmail_product.php');
		return true;
	}else{
		echo '0';
		return false;
	}
}

if(@$_POST['dathang_sim']){
	$sim_id = trim($_POST['id']);
	$name = trim($_POST['name']);
	$email = trim($_POST['email']);
	$phone = trim($_POST['phone']);
	$diachi = trim($_POST['diachi']);
	$content = trim($_POST['content']);
	if($name!='' && $phone!='' && $diachi!='' && $tc->check_email($email)==true){
		$tc->insert_sim_order($name,$email,$phone,$diachi,$content,$sim_id);
		echo '1';
		$qr = mysql_query("SELECT name FROM `sim` WHERE `delete`=0 AND status=1 AND id ='{$sim_id}'");
		$row = mysql_fetch_array($qr);
		$name_sim = $row['name'];
		include_once('sendmail/sendmail_sim.php');
		return true;
	}else{
		echo '0';
		return false;
	}
}

mysql_close();